Walmart Took a Voiceprint 'As Unique As Fingerprints' Without Asking, Suits Say

A lawsuit claims Walmart collected callers’ biometric voiceprints without consent — data that banks use to verify customers.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

A proposed class action lawsuit claims Walmart is collecting biometric voiceprints from Illinois residents who call its stores without first obtaining their consent.

The lawsuit, filed July 6 in the U.S. District Court for the Northern District of Illinois, alleges Walmart's automated phone system captures, stores, and uses callers' voiceprints for fraud detection.[1]

The plaintiff, Illinois resident Amber Smith, says she called Walmart stores three times — twice in December 2025 and again in July 2026 — without knowing the retailer was allegedly collecting a biometric identifier from her voice.

The allegations raise privacy concerns that go beyond an ordinary recorded phone call. A voiceprint can be used to establish someone's identity, and major financial institutions including Chase and Wells Fargo currently use voice biometrics to help authenticate customers.[2][3]

But where does consent factor in?

In this article
Walmart allegedly collected voiceprints without permission
Why your voiceprint is sensitive information
What happens next?

Walmart allegedly collected voiceprints without permission

According to the complaint, callers to Walmart hear an automated message telling them that their call and voice may be recorded for business purposes, including fraud detection.

However, the lawsuit argues that disclosure isn't enough to satisfy Illinois' Biometric Information Privacy Act (BIPA).

Under BIPA, a voiceprint is explicitly classified as a biometric identifier alongside fingerprints, iris scans, and scans of hand or facial geometry.

Before a private company can collect that information, Illinois law generally requires it to tell a person in writing that their biometric information is being collected or stored, disclose why it is being collected and for how long, and receive a written release.

Companies possessing biometric information must also make a written retention policy publicly available and establish guidelines for permanently destroying the data when its original purpose has been fulfilled or within three years of the person's last interaction with the company, whichever comes first.

The lawsuit claims Walmart did none of those things for callers using its automated phone system.

Walmart's privacy notice does disclose that the company may collect biometric information, including voiceprints. It also says Walmart collects personal information when customers speak to customer service using call-recording technology.

But the lawsuit argues putting that information in a privacy policy does not amount to the written disclosure and consent required by Illinois law.

Smith alleges Walmart's system consequently caused customers to "unknowingly surrender" their biometric information.

Why your voiceprint is sensitive information

A voiceprint isn't simply an audio recording of what someone says. Voice biometric systems analyze characteristics of a person's speech to create a representation that can be compared with future samples to help determine whether the speaker is the same person.

That's valuable enough to be used as a security credential.

Wells Fargo currently offers Voice Verification, which uses a customer's "unique voiceprint" along with other identifying information to provide access to account information over the phone.

Chase similarly says its Voice ID technology builds a voiceprint using more than 100 physical and behavioral characteristics, including pitch, accent, and characteristics of a person's mouth and vocal tract. When customers call again, Chase can compare their speech against that voiceprint to verify their identity.

The use of voices as authentication has also become more complicated as AI-generated voice cloning improves.

In a 2023 policy statement on biometric information, the Federal Trade Commission warned that biometric technologies can be misused to create convincing counterfeit voice recordings for impersonation and fraud. The agency has since undertaken a broader effort to address AI-enabled voice cloning.

Even OpenAI CEO Sam Altman has warned financial institutions about relying on voices for authentication.

Speaking at a Federal Reserve conference in July 2025, Altman said he was "very nervous" that some financial institutions still accept voiceprints as authentication, arguing that AI had "fully defeated" voice-based verification and warning of a looming fraud problem.

That doesn't mean someone who obtains a company's stored voiceprint can automatically use it to break into a bank account. Different voice-biometric systems can store and process voice data differently, and Wells Fargo, for example, says it combines its voiceprint with other identifying information.

But it illustrates why biometric data is treated differently from an ordinary piece of personal information; its permanence creates concerns about stolen biometrics. A password can be changed after a breach. Your biological characteristics can't be replaced nearly as easily.

What happens next?

Smith is seeking to represent Illinois residents whose biometric identifiers were allegedly collected through Walmart's automated voice system.

The lawsuit asks the court to find that Walmart violated BIPA and award damages and injunctive relief. Under Illinois law, plaintiffs who prevail can potentially recover $1,000 for a negligent violation or $5,000 for an intentional or reckless violation, or actual damages if they are greater.

The claims have not yet been proven in court, and the case is currently a proposed class action.

Walmart did not immediately respond to All About Cookies' request for comment.

4.8
Editorial Rating
Get Deal
On DeleteMe's website
2026 Editors’ Choice
Best Data Removal for Businesses
Privacy Protection
DeleteMe
PROMOTION: Use the Code PARTNER20 for 20% Off
  • Data removal service that covers 89–986 sites and re-scans every quarter to catch anything that reappears
  • Sends quarterly privacy reports showing what info was found, which brokers had your data, and how long each removal took
  • Includes email masking so you can share a stand-in address instead of your real one

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Walmart Lawsuit Claims Retailer Illegally Collects Illinois Residents’ Biometric Voiceprints From Phone Calls

[2] Voice Verification

[3] Security as unique as your voice